<html>
<head><meta charset="utf-8"><title>workgroup organization · wg-secure-code · Zulip Chat Archive</title></head>
<h2>Stream: <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/index.html">wg-secure-code</a></h2>
<h3>Topic: <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html">workgroup organization</a></h3>

<hr>

<base href="https://rust-lang.zulipchat.com">

<head><link href="https://rust-lang.github.io/zulip_archive/style.css" rel="stylesheet"></head>

<a name="160873498"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160873498" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160873498">(Mar 15 2019 at 13:20)</a>:</h4>
<p>I am pretty new here so there's a high chance I am missing out on some stuff (forgive me in that case!), but I just wanted to raise the question just in case people agree. When I read through all the topics and blog posts and linked repo's I feel like there is a lot of great work that is currently happening, but it feels like there is not a single place where all the knowledge (or at least references to it) come together.</p>
<p>So I thought, maybe we could update the README of the rust-secure-code workgroup with security related projects/area's and work as well? We could also create a separate document for the repository if that would make it more clean. That way beginners / people that want to contribute something on the area of Rust security can get up to speed in a glance.</p>
<p>I think we should also put a link to our Twitter channel for example! (Didn't even knew it existed till today haha :P)</p>



<a name="160873521"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160873521" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160873521">(Mar 15 2019 at 13:20)</a>:</h4>
<p>Since I am new I kind of feel like I might be stepping out of my book here though....</p>



<a name="160873786"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160873786" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160873786">(Mar 15 2019 at 13:23)</a>:</h4>
<p>Maybe it would also be good to close some old topics in our stream as well, or archive them somehow maybe?</p>



<a name="160908701"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160908701" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160908701">(Mar 15 2019 at 20:00)</a>:</h4>
<p>That sounds like a good idea, we do have a bit of a problem with discoverability of work items.</p>



<a name="160921285"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160921285" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160921285">(Mar 15 2019 at 23:12)</a>:</h4>
<p>Mmmm maybe we should start with creating a list of related projects and add those to the README with a description? If you want I can get started with that tomorrow as well!</p>



<a name="160923300"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160923300" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Gerardo Di Giacomo <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160923300">(Mar 15 2019 at 23:53)</a>:</h4>
<p>yep this is a good idea - I would like to spend some time on some work items but I'm really not sure where to start, or who's on point on the tasks, if there's a work tracker for a specific task, etc</p>



<a name="160941921"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160941921" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160941921">(Mar 16 2019 at 08:27)</a>:</h4>
<p><span class="user-mention" data-user-id="144034">@Gerardo Di Giacomo</span> When I started somewhere this week, reading through all topics in this stream provided me with a lot of links! Most of the links themselves also often have links te interesting places :)</p>



<a name="160941965"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160941965" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160941965">(Mar 16 2019 at 08:28)</a>:</h4>
<p>I'll create an issue for it on the WG repo!</p>



<a name="160956070"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160956070" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160956070">(Mar 16 2019 at 15:41)</a>:</h4>
<p>I created an issue for this and I am currently working on collecting different projects that could aid in achieving our Roadmap goals. The issue can be seen here: <a href="https://github.com/rust-secure-code/wg/issues/30" target="_blank" title="https://github.com/rust-secure-code/wg/issues/30">https://github.com/rust-secure-code/wg/issues/30</a></p>



<a name="160956117"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160956117" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160956117">(Mar 16 2019 at 15:42)</a>:</h4>
<p>If you guys all agree, I will leave it open for a week and then create a Pull Request merging the projects that people have mentioned in the issue. Any projects that should be added later then need their own PR.</p>



<a name="160956258"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160956258" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160956258">(Mar 16 2019 at 15:46)</a>:</h4>
<p>Work trackers for specific tasks are on the WG issue tracker. We should probably advertise that in the README</p>



<a name="160956332"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160956332" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160956332">(Mar 16 2019 at 15:49)</a>:</h4>
<p>I would rather keep the list problem-oriented than solution-oriented. I.e. I would rather list the issues we're trying to solve first, and potential solutions second. This leaves room for coming up with novel solutions and/or creating new projects</p>



<a name="160956467"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160956467" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160956467">(Mar 16 2019 at 15:53)</a>:</h4>
<p>I agree! If I understand you correctly, do you mean that you'd first want the README to list the potential problems that we are aiming to solve (For example under a "Problems" or "Topic/Area" heading) and then a list of potential projects that could solve these problems? Or aim to solve security issues in general?</p>



<a name="160956469"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160956469" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160956469">(Mar 16 2019 at 15:53)</a>:</h4>
<p>Or do I misunderstand?</p>



<a name="160958800"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160958800" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160958800">(Mar 16 2019 at 16:59)</a>:</h4>
<p>Actually, do we need another list if we have the bug tracker issues already listing the work items? I guess it would help with visibility if it were in the README</p>



<a name="160958857"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160958857" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160958857">(Mar 16 2019 at 17:00)</a>:</h4>
<p>I don't want to create too much duplication though. So perhaps list the problems we want to solve and link the relevant issues?</p>



<a name="160959308"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160959308" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160959308">(Mar 16 2019 at 17:12)</a>:</h4>
<p>I think that it is a good idea to list the work items in the README! So then the README would look something like:</p>
<p>Introduction<br>
Mission<br>
Work Items (+ Mentioned issues)<br>
Projects (+ Working Group/Security related projects)<br>
Contact</p>
<p>Or should we merge Projects and Work Items together? I personally would prefer having the Work Items / Goals in the README because as an issue they are not really "solvable". For example take "Improve Clippy security lints": When would this really be solved? I think the issue then more or less serves more as an chat/big conversation then an actual issue. Maybe we could move the discussion to Zulip topics and use Github issues for more concretely solvable things? But it might be just a matter of preference however!</p>
<p>I just see now that Twitter was there in the contact section all along... My bad for that...</p>



<a name="160959442"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/160959442" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#160959442">(Mar 16 2019 at 17:16)</a>:</h4>
<p>EDIT: On a second hand, maybe a Github issue is actually a nice way to keep the discussion going. Maybe one of the challenges is to keep Zulip and Github in sync such that the more concrete topics emerging out of Zulip should get their own Github issue. But I am not sure what you guys think about this however.</p>



<a name="161011847"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161011847" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161011847">(Mar 17 2019 at 19:39)</a>:</h4>
<hr>
<p>The list with security related projects I came up with is here: <a href="https://github.com/rust-secure-code/wg/issues/30" target="_blank" title="https://github.com/rust-secure-code/wg/issues/30">https://github.com/rust-secure-code/wg/issues/30</a><br>
I think maybe (in a shorter form, maybe a table per catagory) should be included to the README, such that security-oriented Rust programmers have a way to find all the tools they need which in turn hopefully improves the security ecosystem of Rust.</p>
<p>What do you think of this list? Do you have any other projects to add? Or some which we should exclude?</p>



<a name="161011902"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161011902" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161011902">(Mar 17 2019 at 19:41)</a>:</h4>
<p>Or do you guys think this list should be placed somewhere else? I think keeping all the security related projects / posts together such that newcomers + interested people can get up to speed is fairly important.</p>



<a name="161012166"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161012166" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161012166">(Mar 17 2019 at 19:49)</a>:</h4>
<p>Hmm. I would rather organize the README around the issue tracker items. For example, I want to be able to detect reads from uninitialized memory; libdiffuzz kind of does that, but it's also kind of a hack, and getting proper support for Memory Sanitizer would be much more important.<br>
On the other hand, getting a list of all security-related Rust projects definitely would be helpful - AFAIK right now there is no such thing</p>



<a name="161012346"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161012346" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161012346">(Mar 17 2019 at 19:54)</a>:</h4>
<p>Mmm I can relate with your view. Do you have any idea's on what might be a good place to publish such a list?</p>



<a name="161012367"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161012367" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161012367">(Mar 17 2019 at 19:55)</a>:</h4>
<p>I can create a Pull Request with our work items if you want? Or would you like to do that yourself? EDIT: I get a permission denied when trying to push a branch? :)</p>



<a name="161014432"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161014432" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161014432">(Mar 17 2019 at 20:54)</a>:</h4>
<p>you need to fork your repo and push there, then create a pull request</p>



<a name="161014471"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161014471" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161014471">(Mar 17 2019 at 20:55)</a>:</h4>
<p>this is not <code>bzr</code> where the unit is a branch and you can do whatever you like with them. in <code>git</code> you need to make a copy of the entire repository with all the branches and only after that you can push changes. If you download the code you're also forced to download all branches.</p>



<a name="161014524"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161014524" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161014524">(Mar 17 2019 at 20:56)</a>:</h4>
<p>Ah thanks (Y)! I hope you don't mind me talking to much over here and Github though :) I feel motivated to push some work, but I hope you guys don't find it annoying. If you'd rather have me being silent and just working on some related project feel free :)</p>
<p>I cloned the repo btw, but I will fork it now and then do the pull request! Should be there in a few minutes!</p>



<a name="161014719"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161014719" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161014719">(Mar 17 2019 at 21:02)</a>:</h4>
<p>I opened the pull here: <a href="https://github.com/rust-secure-code/wg/pull/31" target="_blank" title="https://github.com/rust-secure-code/wg/pull/31">https://github.com/rust-secure-code/wg/pull/31</a><br>
Not quite satisfied though, some feedback would be welcome :)</p>



<a name="161014779"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161014779" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161014779">(Mar 17 2019 at 21:03)</a>:</h4>
<p>Thanks, I'll try to take a look tomorrow.</p>



<a name="161014849"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161014849" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161014849">(Mar 17 2019 at 21:05)</a>:</h4>
<p>At a glance, it's probably a good idea to extend verification beyond std... there are commonly used crates such as <code>byteorder</code> that are also critical to the ecosystem, there's no reason not to cover them as well.</p>



<a name="161014931"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161014931" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161014931">(Mar 17 2019 at 21:06)</a>:</h4>
<p>I think that would be nice as well. I read something about Libz Blitz today, but that was a post from 2017, I wonder if they are actually still doing the assessments.</p>



<a name="161015505"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161015505" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161015505">(Mar 17 2019 at 21:21)</a>:</h4>
<p>No, but we could organize something like that</p>



<a name="161015516"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161015516" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161015516">(Mar 17 2019 at 21:21)</a>:</h4>
<p>All we're missing is a clearly defined workflow, some examples and a reddit post announcing it</p>



<a name="161053525"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161053525" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161053525">(Mar 18 2019 at 12:40)</a>:</h4>
<p>We could do something like that I guess. I think it would be nice to have at least 2 people that put their efforts into this. I feel like we either need to do this for the whole 100% and invest time and effort into getting people to join and to organize everything or not to pursue this at all at this moment. Otherwise we would end up like Libz Blitz (or I don't know why it ended, but I guess it was because of a lack of time/participants). We could create an issue for this on the WG repository however. Someone could always pick it up if he/she truly feels like it.</p>



<a name="161060528"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161060528" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161060528">(Mar 18 2019 at 14:14)</a>:</h4>
<p>I  think Libs Blitz ended because it has accomplished what it has set out to do</p>



<a name="161658498"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161658498" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161658498">(Mar 25 2019 at 16:07)</a>:</h4>
<p>I created a Pull Request for the list of projects. <a href="https://github.com/rust-secure-code/wg/pull/32" target="_blank" title="https://github.com/rust-secure-code/wg/pull/32">https://github.com/rust-secure-code/wg/pull/32</a><br>
I am wondering what you guys think.</p>



<a name="161715963"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161715963" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161715963">(Mar 25 2019 at 23:36)</a>:</h4>
<p><a href="https://github.com/japaric/rust-san" target="_blank" title="https://github.com/japaric/rust-san">https://github.com/japaric/rust-san</a> deserves a mention</p>



<a name="161715975"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161715975" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161715975">(Mar 25 2019 at 23:36)</a>:</h4>
<p>TUF is not useful for crate developers, so I'd drop it</p>



<a name="161715980"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161715980" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161715980">(Mar 25 2019 at 23:37)</a>:</h4>
<p>I'd also add an encouragement for the readers to add their own projects there</p>



<a name="161716046"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161716046" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161716046">(Mar 25 2019 at 23:38)</a>:</h4>
<p>Angora currently doesn't work with Rust code, although we very much want that to change</p>



<a name="161716073"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161716073" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161716073">(Mar 25 2019 at 23:39)</a>:</h4>
<p>AFAIR the author of <code>untrusted</code> was moving away from that approach, so not sure if it's a good idea to promote it</p>



<a name="161716150"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161716150" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161716150">(Mar 25 2019 at 23:40)</a>:</h4>
<p>I'd categorize libdiffuzz as a dynamic analyzer, but that's debatable</p>



<a name="161716152"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161716152" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161716152">(Mar 25 2019 at 23:40)</a>:</h4>
<p>Otherwise looks solid to me</p>



<a name="161716181"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161716181" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Shnatsel <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161716181">(Mar 25 2019 at 23:41)</a>:</h4>
<p>Also sorry for the radio silence, I have a lot going on right now</p>



<a name="161717746"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161717746" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> briansmith <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161717746">(Mar 26 2019 at 00:12)</a>:</h4>
<blockquote>
<p>Shnatsel: AFAIR the author of untrusted was moving away from that approach, so not sure if it's a good idea to promote it</p>
</blockquote>
<p>We have been enhancing untrusted recently and there's no intent to drop it. I'm planning to remove it from the public interface of <em>ring</em>, but <em>ring</em> and most of my other projects that do (binary) parsing will continue to use it.</p>



<a name="161717859"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161717859" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> briansmith <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161717859">(Mar 26 2019 at 00:15)</a>:</h4>
<p>I think that it might make sense to decide whether (binary) parsing in general is a category that should be included; if so then zerocopy, nom, combine, scroll, etc. would also be things to consider.</p>



<a name="161734165"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161734165" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161734165">(Mar 26 2019 at 05:54)</a>:</h4>
<p><span class="user-mention" data-user-id="127617">@Shnatsel</span> I will change this things and report back! And no problem :)</p>
<p><span class="user-mention" data-user-id="133214">@briansmith</span> I do consider sanitizing the input / reading inputs securely an important area, but I am not sure what the others think about that :)</p>



<a name="161746889"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161746889" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161746889">(Mar 26 2019 at 10:06)</a>:</h4>
<p>I updated the Pull Request with the suggestions! I processed all suggestions except for removing the untrusted entry.</p>



<a name="161814854"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161814854" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Judson Lester <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161814854">(Mar 26 2019 at 23:57)</a>:</h4>
<p>I'm not sure I understand the assertion that TUF isn't useful to crate authors? They'd be able to sign crates as the author...</p>



<a name="161832555"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161832555" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DevQps <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161832555">(Mar 27 2019 at 06:18)</a>:</h4>
<p>Personally I do not know too much about TUF, so I'll leave that discussion up to you guys :)</p>



<a name="161889330"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/161889330" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Judson Lester <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#161889330">(Mar 27 2019 at 18:51)</a>:</h4>
<p>I mean, TUF is intended as a supply-chain mitigation for services like <a href="http://crate.io" target="_blank" title="http://crate.io">crate.io</a>. It's a parallel registry of artifact signatures. Library owners are one of the stakeholders and participants, since they sign their artifacts (crates) on submission and decide whether to accept unsigned crates.<br>
But it does require a parallel service and maintenance thereof (i.e. someone needs to hold and protect root keys for a TUF registry.) So it's not something that a developer can use on their own.</p>



<a name="162126054"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/146229-wg-secure-code/topic/workgroup%20organization/near/162126054" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Tony Arcieri <a href="https://rust-lang.github.io/zulip_archive/stream/146229-wg-secure-code/topic/workgroup.20organization.html#162126054">(Mar 30 2019 at 15:43)</a>:</h4>
<p>For what it's worth I made (or rather, modified) a proposal to use TUF to secure the <a href="http://crates.io" target="_blank" title="http://crates.io">crates.io</a> index: <a href="https://github.com/withoutboats/rfcs/pull/7" target="_blank" title="https://github.com/withoutboats/rfcs/pull/7">https://github.com/withoutboats/rfcs/pull/7</a></p>



<hr><p>Last updated: Aug 07 2021 at 22:04 UTC</p>
</html>